Paper 2026/2164

On the Limits of LWE and PCE based UPKE

Martin R. Albrecht, King's College London, SandboxAQ
Benjamin Benčina, Royal Holloway University of London
Russell W. F. Lai, Aalto University
Abstract

Updatable Public-Key Encryption (UPKE) enables forward secrecy in asynchronous settings like secure group messaging. At EC'25, Albrecht, Benčina and Lai proposed the first plausibly post-quantum UPKE scheme supporting unlimited updates, based on permutation code equivalence (PCE) over finite fields and hollow lattice problems. However, it has impractically large public keys (4.8MiB) and ciphertexts (1.5MiB). In this work, we first replace the information-theoretic Hollow LHL with a computational assumption secure under binary-secret binary-error LWE, reducing key sizes by an order of magnitude. Second, we show that generalising to Module-LWE is not beneficial: PCE instances over $\mathbb{F}_{q^d}$ admit a linearisation attack via the $q$-Frobenius structure, enabling recovery of secret isometries unless code rates are inflated by $d$, negating any size benefit from module lattices. Third, we establish IND-CCA security in the model of Alwen, Fuchsbauer and Mularczyk (EC'24), but do not achieve `joiner security' like other post-quantum candidates. Finally, we introduce a heuristic multi-key variant using matrix-valued secret keys, enabling efficient encryption of $\ell$ bits per ciphertext. We define the Hinted SPCE assumption to capture the main cryptanalytic challenge and show that the performance gain is likely too small to justify adoption, unless the new assumption can be avoided. Overall, our `unlimited' scheme has update sizes 3.5 to 10 times larger than lattice-based schemes limited to $2^{20}$ updates, depending on the aggressiveness of parameter choices.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Contact author(s)
martin albrecht @ kcl ac uk
Benjamin Bencina 2022 @ live rhul ac uk
russell lai @ aalto fi
History
2026-09-26: approved
2026-09-22: received
See all versions
Short URL
https://ia.cr/2026/2164
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2164,
      author = {Martin R. Albrecht and Benjamin Benčina and Russell W. F. Lai},
      title = {On the Limits of {LWE} and {PCE} based {UPKE}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2164},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2164}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.